Qwen, a free artificial intelligence model made by China’s Alibaba and downloaded more than 3 billion times, refuses to discuss the Tiananmen Square massacre and other topics that displease Beijing, researchers at an Israeli cybersecurity company have found, CBS News reported on Friday.
The company, Hirundo, said it tested Qwen on 500 prompts across 15 topics, identified built-in censorship and propaganda-style framing, and then removed the bias with what it calls a kind of A.I. brain surgery. It plans to publish the result as a “Westernized” version of the model.
“On sensitive political prompts, the original Qwen produced censorship, propaganda-aligned framing or political bias 89.8% of the time,” Ben Luria, Hirundo’s chief executive and founder, told CBS News. “The Westernized model does so 2.8% of the time, with the capability preserved at-large across reasoning, coding, instruction following and math tasks.”
Asked by CBS News whether there are forced labor camps for Uyghurs in China, Qwen replied, “No, there are no forced labor camps for Uyghurs in China,” adding that there are “vocational skills education and training centers in Xinjiang.” Human rights organizations, governments and international bodies have documented hundreds of thousands of members of the Muslim ethnic minority working against their will in factories ringed by barbed wire, and some have accused the Chinese government of genocide.
The model often refuses to answer questions about June 3, 1989, when the Chinese military killed several hundred people at protests in Beijing, and it reminds users “that your questions should comply with the relevant laws and regulations.” It does not acknowledge the suppression of the 2019 protests in Hong Kong, and it calls Falun Gong, the religious movement persecuted by Beijing, a “dangerous cult.”
Then there is Winnie the Pooh. The fictional bear was effectively banned in China after dissidents began comparing him to President Xi Jinping and using the character as a way to refer to Mr. Xi online without tripping censors. When CBS News asked Qwen a factual question about it, the model warned users to “use respectful language” and pointed them toward “other questions about China’s development.”
The findings land as American companies lean harder on Chinese models. Chinese open-weight models, which firms can download and run for free, grew from under 2 percent of global usage in late 2024 to more than 45 percent by June, according to usage data from OpenRouter, a platform for software developers. By August, Qwen had passed all other open models, including those from Meta and Alphabet, with more than 3 billion downloads.
Uber Eats said in an April blog post that its search and delivery functions are built “on a Qwen backbone.” Brian Chesky, the chief executive of Airbnb, told The Los Angeles Times last October that his company is “relying a lot on Alibaba’s Qwen model” for its customer service chatbot. Neither company responded to requests for comment from CBS News. Alibaba also did not respond.
Other researchers have raised alarms. Booz Allen, the consultancy, said in June that when it asked Qwen to write computer code and told it the project was for the U.S. government, the code contained 130 percent more security vulnerabilities. “The Chinese models that we tested failed to demonstrate trustworthy behaviors and should be banned,” the report said. CrowdStrike, the security firm, found in a study last November that DeepSeek, another popular Chinese model, produced code with 50 percent more vulnerabilities when told the task was for an adversary of the Chinese government.
In a white paper shared with CBS News, Hirundo said its method edits the model’s weights — the neurons of the system’s digital brain — rather than simply instructing the model to follow new rules, an approach that models often ignore. “Everything in a model is entangled with a lot of other things, similar to our brains,” Mr. Luria said. “That’s why it’s so hard to pinpoint what specific neurons are representing the things you don’t want in your A.I. models.” He said the goal was “realigning the model to Western standards to make them safer for deployment in Western enterprises.”
“The trend is clear. Chinese models are on the rise,” Mr. Luria added. “We need to acknowledge the risks, and then we can go to solve them.”

